HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Houston City College Exposes 831,642 Student & Alumni Records in ShinyHunters Extortion Breach

In June 2026, Houston City College’s student and alumni data were stolen and publicly released by the ShinyHunters extortion group, affecting over 830 k individuals. The breach underscores the need for robust SOC 2 access‑control practices and continuous audit evidence.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 haveibeenpwned.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
haveibeenpwned.com

Houston City College Exposes 831,642 Student & Alumni Records in ShinyHunters Extortion Breach

What Happened — In June 2026, Houston City College fell victim to a “pay‑or‑leak” extortion campaign run by the ShinyHunters group. The attackers published a data set containing 831,642 unique email addresses together with names, addresses, phone numbers, academic records, citizenship status, dates of birth, gender, and other personal details of current students and alumni.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic credential‑compromise scenario that SOC 2 Access Controls (CC6.1) are designed to prevent and evidence.
  • Continuous monitoring of password hygiene, MFA adoption, and privileged‑account reviews provides the audit‑ready proof points needed after a breach.

Who Is Affected — Higher‑education institutions; students, alumni, and staff whose personal and academic data were exposed.

Recommended Actions

  • Map the breach to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Management) controls; verify that password policies enforce complexity and rotation.
  • Collect evidence of MFA enforcement across all campus systems and document any gaps as remediation tickets.
  • Initiate a formal incident‑response review, update the access‑control policy, and capture the updated policy version as audit evidence.

Technical Notes — The breach originated from a “pay‑or‑leak” extortion model after the attackers obtained the data, likely via stolen credentials or phishing. No specific CVE is associated. Exfiltrated data includes academic records, citizenship status, DOB, contact information, and gender. Source: Have I Been Pwned – Houston City College breach

📰 Original Source
https://haveibeenpwned.com/Breach/HoustonCityCollege

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →